Admin Profile

Updated Oct 4, 2026 Markdown

GET /api/v1/admin/profile

Get admin profile

Returns the current admin's profile (username, email, language, avatar URL, 2FA state).

Responses:

Status Schema Description
200 ApiSuccess_AdminProfileResponse_ Successful Response

Response example (200):

JSON
{
  "data": {
    "avatar_url": "...",
    "email": "",
    "language": "auto",
    "last_login": "...",
    "sidebar_collapsed": "...",
    "two_factor_enabled": false,
    "two_factor_method": "",
    "username": "alice"
  },
  "message": "",
  "status": "success",
  "warnings": [
    "string"
  ]
}

cURL example:

shell
curl -X GET \
  -H "X-WHost-Key: $WHOST_API_KEY" \
  -H "X-WHost-Timestamp: $(date +%s)" \
  -H "X-WHost-Nonce: $(openssl rand -hex 16)" \
  -H "X-WHost-Signature: $(compute_hmac)" \
  https://your-server:2000/api/v1/admin/profile

PUT /api/v1/admin/profile

Update admin profile

Patch email, language and/or the sidebar choice. Session-only — HMAC keys cannot mutate admin credentials. The sidebar choice is kept in the agent's admin state file, not in agent.conf.

Body fields:

Field Type Required Notes
email string no —
language string no —
sidebar_collapsed boolean no The sidebar choice to keep: true collapsed, false expanded.

Request body example:

JSON
{
  "email": "string",
  "language": "string",
  "sidebar_collapsed": false
}

Responses:

Status Schema Description
200 ApiSuccess_AdminProfileResponse_ Successful Response
422 HTTPValidationError Validation Error

Response example (200):

JSON
{
  "data": {
    "avatar_url": "...",
    "email": "",
    "language": "auto",
    "last_login": "...",
    "sidebar_collapsed": "...",
    "two_factor_enabled": false,
    "two_factor_method": "",
    "username": "alice"
  },
  "message": "",
  "status": "success",
  "warnings": [
    "string"
  ]
}

cURL example:

shell
curl -X PUT \
  -H "X-WHost-Key: $WHOST_API_KEY" \
  -H "X-WHost-Timestamp: $(date +%s)" \
  -H "X-WHost-Nonce: $(openssl rand -hex 16)" \
  -H "X-WHost-Signature: $(compute_hmac)" \
  -H "Content-Type: application/json" \
  -d @body.json \
  https://your-server:2000/api/v1/admin/profile

POST /api/v1/admin/profile/2fa/backup-codes/regenerate

Regenerate backup codes

Issues a fresh batch of one-time backup codes. Old codes are invalidated.

Responses:

Status Schema Description
200 ApiSuccess_BackupCodesResponse_ Successful Response

Response example (200):

JSON
{
  "data": {
    "codes": [
      "..."
    ]
  },
  "message": "",
  "status": "success",
  "warnings": [
    "string"
  ]
}

cURL example:

shell
curl -X POST \
  -H "X-WHost-Key: $WHOST_API_KEY" \
  -H "X-WHost-Timestamp: $(date +%s)" \
  -H "X-WHost-Nonce: $(openssl rand -hex 16)" \
  -H "X-WHost-Signature: $(compute_hmac)" \
  https://your-server:2000/api/v1/admin/profile/2fa/backup-codes/regenerate

POST /api/v1/admin/profile/2fa/disable

Disable 2FA

Requires the current admin password. Clears stored TOTP secret + backup codes.

Body fields:

Field Type Required Notes
password string yes minLength=1

Request body example:

JSON
{
  "password": "REPLACE_ME"
}

Responses:

Status Schema Description
200 MessageResponse Successful Response
422 HTTPValidationError Validation Error

Response example (200):

JSON
{
  "message": "string",
  "status": "success"
}

cURL example:

shell
curl -X POST \
  -H "X-WHost-Key: $WHOST_API_KEY" \
  -H "X-WHost-Timestamp: $(date +%s)" \
  -H "X-WHost-Nonce: $(openssl rand -hex 16)" \
  -H "X-WHost-Signature: $(compute_hmac)" \
  -H "Content-Type: application/json" \
  -d @body.json \
  https://your-server:2000/api/v1/admin/profile/2fa/disable

POST /api/v1/admin/profile/2fa/enable

Verify OTP and enable 2FA

Verifies the OTP from /2fa/setup and activates 2FA. Returns the one-time backup codes — they cannot be retrieved later. Anti-replay: rejects re-use of the same TOTP step.

Body fields:

Field Type Required Notes
code string yes minLength=6; maxLength=6; pattern=^\d{6}$

Request body example:

JSON
{
  "code": "string"
}

Responses:

Status Schema Description
200 ApiSuccess_BackupCodesResponse_ Successful Response
422 HTTPValidationError Validation Error

Response example (200):

JSON
{
  "data": {
    "codes": [
      "..."
    ]
  },
  "message": "",
  "status": "success",
  "warnings": [
    "string"
  ]
}

cURL example:

shell
curl -X POST \
  -H "X-WHost-Key: $WHOST_API_KEY" \
  -H "X-WHost-Timestamp: $(date +%s)" \
  -H "X-WHost-Nonce: $(openssl rand -hex 16)" \
  -H "X-WHost-Signature: $(compute_hmac)" \
  -H "Content-Type: application/json" \
  -d @body.json \
  https://your-server:2000/api/v1/admin/profile/2fa/enable

POST /api/v1/admin/profile/2fa/resend-code

Resend email 2FA code

Only valid mid-setup when method=email. Response data: {masked_email}.

Responses:

Status Schema Description
200 ApiSuccess_dict_str__Any__ Successful Response

Response example (200):

JSON
{
  "data": {},
  "message": "",
  "status": "success",
  "warnings": [
    "string"
  ]
}

cURL example:

shell
curl -X POST \
  -H "X-WHost-Key: $WHOST_API_KEY" \
  -H "X-WHost-Timestamp: $(date +%s)" \
  -H "X-WHost-Nonce: $(openssl rand -hex 16)" \
  -H "X-WHost-Signature: $(compute_hmac)" \
  https://your-server:2000/api/v1/admin/profile/2fa/resend-code

POST /api/v1/admin/profile/2fa/setup

Initiate 2FA setup

Begin two-factor enrollment. method=totp returns the secret + otpauth:// URI for QR rendering. method=email sends an OTP to the configured admin email and returns the masked address.

Body fields:

Field Type Required Notes
method string no default totp; pattern=^(totp|email)$

Request body example:

JSON
{
  "method": "totp"
}

Responses:

Status Schema Description
200 ApiSuccess_TwoFASetupResponse_ Successful Response
422 HTTPValidationError Validation Error

Response example (200):

JSON
{
  "data": {
    "masked_email": "...",
    "method": "totp",
    "otpauth_uri": "...",
    "secret": "..."
  },
  "message": "",
  "status": "success",
  "warnings": [
    "string"
  ]
}

cURL example:

shell
curl -X POST \
  -H "X-WHost-Key: $WHOST_API_KEY" \
  -H "X-WHost-Timestamp: $(date +%s)" \
  -H "X-WHost-Nonce: $(openssl rand -hex 16)" \
  -H "X-WHost-Signature: $(compute_hmac)" \
  -H "Content-Type: application/json" \
  -d @body.json \
  https://your-server:2000/api/v1/admin/profile/2fa/setup

DELETE /api/v1/admin/profile/avatar

Delete admin avatar

Removes the avatar file from disk and clears the persisted URL. Response data: {avatar_url: null}.

Responses:

Status Schema Description
200 ApiSuccess_dict_str__Any__ Successful Response

Response example (200):

JSON
{
  "data": {},
  "message": "",
  "status": "success",
  "warnings": [
    "string"
  ]
}

cURL example:

shell
curl -X DELETE \
  -H "X-WHost-Key: $WHOST_API_KEY" \
  -H "X-WHost-Timestamp: $(date +%s)" \
  -H "X-WHost-Nonce: $(openssl rand -hex 16)" \
  -H "X-WHost-Signature: $(compute_hmac)" \
  https://your-server:2000/api/v1/admin/profile/avatar

POST /api/v1/admin/profile/avatar

Upload admin avatar

Accepts PNG / JPEG / WebP up to 2 MB (magic-byte validated). Response data: {avatar_url} — short cache-busted URL to /avatar/raw.

Body fields:

Field Type Required Notes
avatar string yes —

Request body example:

JSON
{
  "avatar": "string"
}

Responses:

Status Schema Description
200 ApiSuccess_dict_str__Any__ Successful Response
422 HTTPValidationError Validation Error

Response example (200):

JSON
{
  "data": {},
  "message": "",
  "status": "success",
  "warnings": [
    "string"
  ]
}

cURL example:

shell
curl -X POST \
  -H "X-WHost-Key: $WHOST_API_KEY" \
  -H "X-WHost-Timestamp: $(date +%s)" \
  -H "X-WHost-Nonce: $(openssl rand -hex 16)" \
  -H "X-WHost-Signature: $(compute_hmac)" \
  -H "Content-Type: application/json" \
  -d @body.json \
  https://your-server:2000/api/v1/admin/profile/avatar

GET /api/v1/admin/profile/avatar/raw

Stream admin avatar binary

Returns the image bytes with the original Content-Type. Honors If-None-Match for 304 caching. Binary — no JSON envelope.

Responses:

Status Schema Description
200 — Successful Response

cURL example:

shell
curl -X GET \
  -H "X-WHost-Key: $WHOST_API_KEY" \
  -H "X-WHost-Timestamp: $(date +%s)" \
  -H "X-WHost-Nonce: $(openssl rand -hex 16)" \
  -H "X-WHost-Signature: $(compute_hmac)" \
  https://your-server:2000/api/v1/admin/profile/avatar/raw

PATCH /api/v1/admin/profile/password

Change admin password

Requires current password. On success the session secret is rotated (invalidating every other session) and a fresh session cookie is issued for the caller.

Body fields:

Field Type Required Notes
current_password string yes minLength=1
new_password string yes At least 8 characters and at most 72 bytes when UTF-8 encoded.; minLength=8; maxLength=128

Request body example:

JSON
{
  "current_password": "REPLACE_ME",
  "new_password": "REPLACE_ME"
}

Responses:

Status Schema Description
200 MessageResponse Successful Response
422 HTTPValidationError Validation Error

Response example (200):

JSON
{
  "message": "string",
  "status": "success"
}

cURL example:

shell
curl -X PATCH \
  -H "X-WHost-Key: $WHOST_API_KEY" \
  -H "X-WHost-Timestamp: $(date +%s)" \
  -H "X-WHost-Nonce: $(openssl rand -hex 16)" \
  -H "X-WHost-Signature: $(compute_hmac)" \
  -H "Content-Type: application/json" \
  -d @body.json \
  https://your-server:2000/api/v1/admin/profile/password
Still Need Help?

Our support team is here around the clock for anything you can't find above.